Loopholes in Google’s data safety labels
foundation.mozilla.org
foundation.mozilla.org
> As we’ve noted, data sharing with “service providers” is exempt from disclosure requirements.
> Many different companies act as service providers, including Google itself
Well, whaddya know. Apps don't have to report whether they share data with Google.
I found it striking that in the list of four questions that Mozilla asked Google, not one of them elicited a straight answer. I don't mean just evasive or slippery; they failed to answer the question, instead answering a different question, one that wasn't asked.
Politicians do this all the time. Constantly. They do it because the PR firms taught them to do this, and those same PR people work for tech companies now.
(It's awful that journalists these days let politicians get away with it. When I went to journalism school, we would get a failing grade if we allowed an interview subject to dodge a question like that, but that's a rant for another day.)
https://www.youtube.com/watch?v=X5ExYQ21sGY
The sad part is, that the politician asking the question does a better job that most journalists and points at the absurdity of the dodged answers.
That, or they do fun stuff like giving this splash screen on a new update:
https://imgur.com/a/p4CVBHb "Power and privacy to the people. No need to dig into your security settings. Fierce privacy is our default."
You know, the browser that defaults to Google search and having search suggestions on. I know I'd have a couple privacy settings to change.
And having opt-out telemetry with very limited messaging that it occurs.
I see that Mozilla has started pushing Pocket again. With the last upgrade, I got a new tab with a full-page Pocket ad. They don't need telemetry to discover that I've never used Pocket. I dislike their custom of using upgrades to stuff an ad in my face; and I dislike that scarce screen real-estate is used for an unnecessary button. If they've got to create a new tab on upgrade, it should show the changelist, not a "promotional message".
It's a bloody plug-in, and it should be possible to unplug it.
A1: we never review the disclosures. We have reviewed zero apps for discrepancies in the last year.
A2: since we never check (refer to A1), it can get as bad as it likes, and would you please be quiet because we’re trying to remain wilfully ignorant over here!
A3: we have taken zero enforcement actions in the last year (surely you understood that from our first answer?).
A4: ARGH! WHY ARE YOU TELLING US ABOUT PROBLEMS? WE DON’T WANT TO KNOW OR WE MIGHT HAVE TO DO SOMETHING ABOUT IT! Y’know. Something.
I worked for a company whose business Google account was somehow deleted. The access to Gmail was entirely lost, which was super critical for the company. One of our employees spent hours dealing with Google customer support. If I'm not being mistaken here, the response that they kept getting from Google was something along the lines of "due to our data safety and data retention policies, we are not able to recover your Google account". That same phrase was repeated again and again by various Google reps. Long story short, the company recovered everything. The solution was to email one of the investors and ask them if they can help in any way.
It was hilarious. The mail thread was something like:
Company:
> Hey Joe, due to xxxxx, we lost access to yyyyy@yyyyy.com. Google customer support cannot do anything. Any ideas what shall we do?
Joe forwards the email to an internal Google employee with just two words:
> Handle this.
The account is fully back online within 30 minutes.
There's a story of a car company which calculate the cost needed to recall a defective model (safety-wise), versus the fines needed to pay times the possibility that the error may occur. There's cheaper on the later so they don't do the recall.
And the recent train derailments, many people said that if the fines are lower than the reduced cost they get for lowering the safety, they'll keep doing it again.
Yes, there are many companies that do good things, and some that exist solely to do good things.
The difference is that they focus on doing those good things, so they don't show up in headlines very often.
Neither the dollar as the object of transaction nor the system of accounting (accounting for resource allocation) called capitalism, have any real connection to the underlying drivers. The same problems existed in many other means of transacting (currency) and economic systems (communism notoriously being a sprint towards corruption).
Unfortunately, people have forgotten or have intentionally been misled from realizing the tacit type of self-regulating controls of a system like actual capitalism (you lose money when making bad decisions, you aren’t rewarded by thieving friends in government) and even aristocracy, where you had to maintain a certain balance of relationships even with the peasants in order to prevent being made a foot shorter.
Ironically, the rather tyrannical caste that has we emerged on Mt Davos is forgetting that sometimes the dumb and easily manipulated peasantry the technocrats see themselves as being benevolent demigod leaders of, don’t take so kindly to their shenanigans, with dire consequences for all.
I mean what are you, a bigot, racist, sexism homophobe for questioning the beneficent and glorious, exhaled rule of the Ruling Gods over your life and limitations on what you can do, say, and think? You better. Don’t get any ideas or your gods on Mt Davos will strike you down with ban hammers.
Capitalism provides a moral justification for the actions of greed, it makes responding to those incentives seem inevitable and necessary and so not the responsibility of the person actually doing it.
Neither of those is necessarily inherent to capitalism, I guess, but they are certainly part of the structure of the capitalism we live with so shouldn't be dismissed either.
You may be referring to the favorite alternative method for accounting under the inherently fraudulent system that fraudulently calls itself communism, while hating and having nothing at all to do with community, which allocates resources, i.e., means of production, by central committee that sees itself as some kind of contemporary gods on earth.
The means of production are a separate thing and are generally separate from gore they are accounted for and allocated for some purpose.
To simplify, you having the skill, told, and wood to create a bookshelf are the means of production; your method and decision making that lands you on making a bookshelf instead of book ends or something else, is where you could use capitalist or “communist” practices to determine that, Party of which is accounting for the resources and drawing a conclusion as to what to do.
Saying that Google or their employees are evil for doing the thing they're supposed to do is pointless. If they don't do <evil thing>, a competitor will do <evil thing>. The only way to save the world from <evil thing> is to make it illegal (and preferably with criminal penalties, not just small fines), so that corporations can avoid doing it without worrying about the competitive risks.
(although Google and all of big tech are evil monopolists and they need to be broken up)
https://mattstoller.substack.com/p/on-lina-khan-derangement-...
This line of thinking bothers me more than it probably should. How can corporations be thought of as separate entities from the people it consists of, in any context except legal? I wrote a lot more, but decided to distill it into one question: How can they be, in good conscience, allowed to get a pass?
Consider the CEO of Google growing a conscience (hypothetically ofc). If he decides to cut back on <evil things> for the good of society, then society will benefit, but Google shareholders will lose. The impact will be measurable in financial statements, and when the board meets to vote on a new CEO, they’ll replace him with someone who will do a better job of making those numbers go up (aka someone without that conscience). The system self-corrects in the long run!
The CEO has a legal obligation to protect the interests of share holders (“fiduciary duty”). So from that perspective, a CEO acting in the interests of society rather than shareholders is breaking the law, and could be personally liable.
The incentives in the system are not set up in such a way that corporations could be reasonably expected to “self police” in a way that benefits society at the expense of shareholders. Sure, in some cases it’s possible to have a win-win scenario, where everyone benefits, but those are extremely rare.
IMO this is a good system because it leads to the primary producers to perform at peak efficiency, but it doesn’t work unless it’s balanced by government regulation, which is something that the government has been miserably failing at for the past two decades (at least)
> How can [corporations] be, in good conscience, allowed to get a pass?
I sort of expected you to answer that corporations don't get a pass. I agree with your premises:
1) corporations will follow their own incentives
2) legislation is the means for "caring for society"
3) legislation changes a company's incentives and should be enforced
It goes against the Zeitgeist simply because Americans understand that their representatives and senators are largely corrupt (regulatory capture) so enforcement and legislative remedies are a pipe-dream until we deal with legislative corruption.
https://finance.yahoo.com/quote/GOOGL/holders/
https://finance.yahoo.com/quote/AAPL/holders/
The only real solution is to give the employees of the corporation the degree of power when it comes to selecting the executive cohort as the shareholders of the corporation have - i.e. a 1 : 1 ratio. Germany does this to some extent.
The other option is more radical - eliminate the shareholder system of devolved liability entirely, and only allow the people who work within a corporation to own shares in that corporation. (Note that the traditional communist-socialist approach would be to simply replace the shareholders with a governmental central committee while keeping the structure essentially the same.)
Ugh this. Trying to search for almost any generic phrase or term just floods the results with links to shops and "TOP 10 BEST thingYouSearched"
Google Search feels almost useless now for anything other than shortcuts [in]to websites you already know about.
In my experience, not even that. I used to be lazy and use google search to get to websites I knew, but it can no longer find them even if I type it in exactly! So I've mostly had to revert to making sure I bookmark the sites and go in that way. (And of course I've switched to ddg for search.)
eBay is the worst for this.
"Pancreatic cancer now on sale at eBay!"
"The best Libertarian Morals now on sale at eBay!"
"Buy discount Rings of Saturn now at eBay!"
Google's business model is built around privacy invasion and data collection.
Mozilla's business model is built around Google.
Process these as you see fit.In the same way you reconcile Mozilla's privacy concerns with the fact that every Firefox install gets tagged with a unique digital fingerprint and keeps a persistent websocket connection open in the background.
I don't think that's fair, especially since they have already dropped it.
> In the same way you reconcile Mozilla's privacy concerns with the fact that every Firefox install gets tagged with a unique digital fingerprint
I'm not sure what you're on about here. Care to elaborate?
> and keeps a persistent websocket connection open in the background.
Hadn't heard of this one before. Do you have sources?
Dropping it doesn't change the duplicity that existed for almost 2 decades.
Hadn't heard of this one before. Do you have sources?
https://borncity.com/win/2022/03/22/firefox-installer-weist-...
It was dropped in 2015, 17 years after Google's foundation. Are you saying they were evil from the beginning? I couldn't tell but at least for their first decade or so they seemed to be trying to do good. In any case, it's very different to be Google and evil vs. Mozilla/Firefox having a unique ID in some downloads.
Why do I say some downloads? Because that ID is assigned when you click the link on their website's downloads page. If you get it from your package manager, which I suspect a very large portion of their user base does, you don't get uniquely identified. If you download from any mirror or otherwise free software download store, you don't get uniquely identified.
What you are downloading in most cases is just an installer executable -- no software included. The installer pulls the actual software from Mozilla's server. Each copied served is given a unique ID and is unlike any other -- easily proven by hash or checksum (Mozilla calls this a "dltoken", see my reference above).
- https://mozilla-firefox.fileplanet.com/ - Indeed it downloads a download manager.
- https://download.cnet.com/Mozilla-Firefox/3000-2356_4-102085... - Downloads an installer. It's for an older version but shouldn't have the unique ID, and it should be able to update itself but I haven't tested.
- https://techviral.net/firefox-offline-installer/ - Also the installer, and for the latest version.
That's 2 out of 3 without an unique ID.
You have also conveniently glossed over the package manager angle, which I suspect is a pretty large slice of their user base.
Firefox install fingerprinting: https://www.ghacks.net/2022/03/17/each-firefox-download-has-...
Persistent web socket connections: https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf (page 8-9)
In both cases this "telemetry" is something that the user did not ask for or authorize, nor is it disclosed prominently.
That's fair, but "the right thing" for whom? If it's for their shareholders, which apparently by law is in fact not only the right thing but a requirement, then it's hard to argue they're not good on their word.
> Firefox install fingerprinting: https://www.ghacks.net/2022/03/17/each-firefox-download-has-...
I commented on the sibling. This is only true if you download it directly from their website. Firefox is acquired from many other sources - package managers, FTP sites, other free software distributors...
> Persistent web socket connections
Thanks, this does seem less than ideal. There seems to be zero evidence of any breach of anonimity via this mechanism though. Just to be clear, I agree that it shouldn't be this way.
> In both cases this "telemetry" is something that the user did not ask for or authorize, nor is it disclosed prominently.
No argument here. I both agree with your assessment and that this is a bad thing.
Firefox's market share has done nothing but decline for decades --- and Google still pays.
The fact that Mozilla are failing at their business model doesn't mean that's not the model.
So my argument stands.
Mozilla's current deal with Google is good through 2023 and is worth around $400-$450 million per year.
Every deal Mozilla has made with Google has payments increased --- even as Firefox's browser share has decreased.
https://www.androidheadlines.com/2020/08/mozilla-firefox-goo...
This article [0] from 2018 suggests an uptick, but it justifies it as "a deal to get paid for Google search traffic in parts of Europe" - so, actual market expansion.
I'm not saying you're wrong, only that I haven't seen evidence that you're not.
[0] https://www.cnet.com/tech/services-and-software/google-firef...
Google does not care about Firefox's market share. Google only cares that there is an appearance of competition in the browser market.
This is their own data on the matter... https://data.firefox.com/dashboard/user-activity
They've lost about 50 million users between 2019 and 2023 - roughly 20% of the 2019 totals.
In my opinion - Google pays because having a well known name that they can claim is still competing in the browser space is beneficial to them with regards to antitrust and monopoly laws. The ad revenue from the Firefox user base helps to make that cost manageable.
Mozilla business model is entirely built around their market share. As such, they are in a much more difficult situation than Google's Chrome team. If Mozilla has a difficult time (financially), they are more likely to do shady things than the Chrome team which has no such pressure. For example, the Chrome team would never accept any cryptocurrency deal; something that I have no difficulties imaging Mozilla to do.
Obviously, Chrome will not actively hurt Google's other businesses (specifically ads), but Chrome's primary goal is to make the web a better place. The worst case scenario for Google is that the web (and thus their revenue stream) disappears.
For the sake of children, to defeat the terrorists... :)
What do you reckon: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Mozilla is taking a principled stance that _all_ sharing of data should fall into the same category of "we gave your data to someone else", but I think there's a much more pragmatic breakdown. Data can either be not-shared, shared to service providers with contractual obligations to treat that data as owned by the original service, or shared to service providers who may then use and further share that data for their own purposes.
Examples of the latter two would be the difference between sending crash reports to a crash reporting service that doesn't interpret user data in any way and is only a mechanism used by the original service, vs, say, sending it to Facebook to report an advertisement conversion, where it will be used to further the Facebook ad modelling.
As a privacy conscious user I typically don't mind the former, but despise the latter. Mozilla does not appear to distinguish between these two cases. One could argue that the former is still increasing the scope of data being hacked, or that companies might breach their contracts and use it anyway, but if you assume illegality then most of this breaks down anyway, we have to assume that companies stick to the law and their contracts for any of this to be of any use (and I think that's mostly reasonable for us to do).
I work closely to this area at Google so I don't want to comment on how this fits with Google's data safety labels and the privacy policies of apps. I think people should read the documentation and draw their own conclusions.
I personally think that this issue sits at the intersection of principles and pragmatism – making information correct but conveying a less immediately useful message, vs making information accessible and actionable for the majority of users. Google (and Apple) also still need to appeal to developers to get them to build for their platforms, and that again may require pragmatism.
To follow up, this distinction is also made by both GDPR in Europe, and CCPA in California. (In fact, CCPA uses the same term "Service Provider" and I wouldn't be surprised if that's where Google got it from.)
Still, both GDPR and CCPA require disclosure of Processors/Service Providers.
Transfers to a Processor/Service Provider have restrictions, and that's significant. Such third parties are treated differently under the law, with those restrictions removing the need for other safeguards. But the don't entirely remove any risk.
Ultimately one of the goals of these disclosures is letting the user take control over how their data is used and distributed. Some users (including you, and including myself) are comfortable with data transfers that are protected by legal safeguards rather than technical ones. Some are not comfortable with that, and have valid reasons to be. Some users reasonably want to know their full security risk exposure, which means being aware of which parties are handling their data. Some users simply don't want to do business with certain platform providers, even indirectly.
I'll also point out that the EU has found that US safeguards about transfers to Service Providers are inadequate, because if a third party has your data that means US law enforcement can get your data from that third party. So there are very valid concerns that the safeguards Google considers adequate for a Service Provider may not satisfy all users.
All of which is to say, I agree that the distinction about Service Providers is useful and meaningful, but I think it is the wrong decision to exempt Service Providers from being listed altogether.
It sounds like, apart from companies breaking the law, the only caveat to service providers being "safe" from user data sharing is law enforcement, and in particular US law enforcement.
While this is something I care a lot about, I think many people would consider data use for profit, and data use for law enforcement substantially different, so it _may_ be reasonable for Google not to count law enforcement in their system design. This is a hypothetical, I don't know if this was a factor and I don't really hold this opinion, but I could understand it.
You have to assume not necessarily blatant illegal behavior, but instead a slow stretching of the law. There is huge financial motivation for a company to switch a data pipeline from the former use case to the latter. Those incentives will push them towards changing the fine print or creative interpretations of that fine print, or will get them acquired by a more profitable, less scrupulous company willing to do so. Look at the incentives, and that will tell you what the outcomes will eventually be.
The only way to avoid this is either not sharing the data in the first place, or sharing the data only after it's encrypted so that the service provider cannot help but treat it as owned by the original service. Anything else is fighting a losing battle.
I don't "people are going to break the law so let's not do anything" is the most pragmatic response. I don't disagree, and can certainly empathise with it, but I do see it as closer to Mozilla's principled stance than to what I think most people would be happy with (assuming they had the facts, which most don't).
Apple came up with this "nutrition label" idea for app usages of data that is self reported by developers. Everyone assumed "increase in privacy". Google copied the practice and it's full of "loopholes" now.
This whole data privacy, unlike cryptography, has become more of a marketing tactic and media loves to create super villains and super-heros out of it. There's no substance here.
> Apple’s plan to make iPhone apps be transparent about the data they take falls short of being helpful — or even accurate
Seems like letting the user enter an email address to recover his password counts as email collection (he cannot subscribe, provide or see his email using the app, hence the initial form I submitted).
> "Additionally, a new Commerce Department report cited Apple and Google as “gatekeepers” of mobile app stores, leaving consumers at the mercy of their pricing and selection. The report calls for new legislation that would boost competition in the mobile app market, which would help both consumers and app developers."
To extend the FDA analogy, we don't really require stores that sell products to be held responsible for flaws in or problems with those products, e.g. contaminated baby formula. The onus should be on the manufacturer (or the app developer) - but this also means that if a store sells a certain brand (e.g. Whole Foods 365 brand) then they are directly responsible for any issues with that product.
* Based on my own experience over the years actually reading them as someone who both cares about this stuff and works in the space.
If Google decides to not fund it next year it's bad management on FFs part.
Putting all your eggs in one basket is very risky and puts you in a place where you may have an ugly compromises Vs face bad consequences..
Why? What does Google get from it? How do they justify this expense internally?
Being the default search has value. It's why Google pays Apple billions a year for the same thing.
There is no explicit loss of value for Google, they save money + get more chrome users..
Now if MS comes into play or are already playing in the background, then is a totally different story..
So its like a "sue yourself" system? :-D
This paper looks at iOS developers. We found that there was a lot of misconceptions and misunderstandings that led to under-reporting as well as over-reporting of behaviors. For example, on iOS, "tracking" is defined only in the context of advertising. A lot of people also misunderstood what "Data Linked to Users" means https://dl.acm.org/doi/fullHtml/10.1145/3491102.3502012
Our research team has also been crawling these labels on both Apple App Store and Google Play to understand changes in labels over time. One early result is that these nutrition labels are not updated very often. https://dl.acm.org/doi/fullHtml/10.1145/3491101.3519739
Lastly, we've developed an IDE plugin for JetBrains to help developers fill out labels more accurately (and hopefully more easily too) for Google Play. The key idea is to have developers add privacy annotations (in the form of Java annotations) directly into their code. The plugin uses a bunch of heuristics to flag where you might need an annotation, and helps you fill out those annotations. These annotations are then used to generate a CSV file that can be uploaded to Google Play. https://matcha-ide.github.io/
I also have a talk called Helping Developers with Privacy. It summarizes the last decade of our team's research on this topic. (Note that Slideshare has become a bit spammy, inserting ads in between slides, sorry about that) https://www.slideshare.net/jas0nh0ng/helping-developers-with...
Stepping back, our team has been looking at two big ideas for privacy. One is these privacy annotations. I think annotations has the potential to be transformative for the privacy ecosystem. They can help developers, they can be assisted with IDE tools, they can be embedded into compiled code, they can be used to help auto-generate privacy user interfaces, and can also be used as a major hint to check the behavior of the apps (by app stores, by auditors, by journalists, and by researchers).
The second is that every app should have a simple manifest that whitelists an app's privacy-related behaviors. The manifest describes what data will be used and a chain of transformations, similar to Unix pipes. In the context of smart homes, an example might be: get access to microphone -> transform to loudness -> send to sleep.com. While we don't know exactly what sleep.com will do with the data, we can have more assurance that it's not sending raw microphone data. Here's a paper at Oakland Security that describes our ideas. An interesting part of our initial analysis is that the vast majority of apps don't need raw data (raw microphone data, GPS data, logs, etc). Rather, they need a processed and more granular form of it (e.g. loudness, what city you are in, etc). http://haojianj.in/resource/pdf/peekaboo-preprint.pdf
Happy to chat more about these topics, we've been working on privacy for quite a while and have had some successes with industry and with the US Federal Trade Commission.
I'm not sure why mozilla is wasting their time criticizing detail mismatches -- the self-report system only creates accountability for relatively well meaning players who are large enough to 1) be worth auditing and 2) have reputational risk
little snitch everywhere
Mozilla Corporation did, and they put it in Firefox and you can't opt-out
You sort of can, but you need to manually dig through tens of hidden options in about:config.
Always breaks my heart to see corporate speak creep into normal speak :(
Btw, "Executive Summary" being listed under "Summary" also seems weird. I'd call that a table of contents.
Feeling particularly nitpicky today.
In other words, an executive summary is the summary for a non-expert stakeholder. In practice you use this to tell the executive what you want them to think.
...no, an executive summary is not "a summary for a clueless executive". An executive summary provides enough information to act on the material... that is, a summary that promotes executive function[0], otherwise known as decision-making based on what it is summarizing.
The "executive" here is not a noun, it's the same "executive" as in "executive function" and "executive decision". And yes, it's also where the job role gets its name.
I understand, but in this case that’s a distinction without a difference. For whom is the executive summary? For the person making the executive decision, ie the executive.
In my career, executive summaries are crafted to guide the executive to the outcome desired by the author. Perhaps that’s unique to my experience.